CVE-2026-81676
Multiple Vulnerabilities in TOOOLS' iSquad
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system.
| CWE | CWE-89 |
| Vendor | toools |
| Product | isquad |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for toools isquad
Be the first to know when new unknown vulnerabilities affecting toools isquad are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TOOOLS / iSquad
0 < 22/07/2026
References
Credits
DylanCV